SMS to me is solely the channel for machines to force a bad MFA implementation on me and couriers to tell me something is on the way/nearly there/delivered. All person to person comms, without exception, iPhone or Android users, is via WhatsApp. Anecdata from UK.
I think the argument about SMS being insecure is very real but exaggerated. We send password reset with capability URLs through non encrypted mail. Sure, the channel is most likely encrypted but anyone at mail service providers could easily take over a massive amount of accounts. Although the user would notice at least.
Sure, there are tools to intercept SMS without the user noticing, but as a second factor an attacker still doesn't have access to other factors.
The successor RCS has the problem that users cannot reset the password. If you are compromised you need to urgently contact your ISP.
To be clear, I don't consider it to be bad for primarily security reasons, I consider it to be bad because it's inconvenient when it's the only option and forced. I would always prefer TOTP or a push based system such as WhatsApp or telegram or similar. SMS can be slow, and uses an application I don't open for any other purpose.